Note: Hyperproof connects to many third-party systems that frequently change, including the system interface. Contact your System Administrator or the third-party provider for assistance in meeting the requirements to integrate with Hyperproof and collect the proof you need.
When you create a Hypersync between Hyperproof and Okta, you can automatically collect the following proof types:
Okta proof types and fields
Proof type | Fields | Testable |
Directory Integrations | Integration Name, Integration Type, Integration Status, Agent Name, Agent Status, Agent Version, Agent Up to Date, Last Connection | Yes |
Global Session Policies | Policy name, Rule name, Idle timeout (hours), Max session lifetime (hours), Users affected, Status | Yes |
Group Membership List | Person, Username, Primary Email, Status, Description | Yes |
List of Admins | Domain, Name, Email, Role | Yes |
List of API Tokens | ID, Name, Expiration Date, Creation Date, Last Updated | Yes |
List of Deactivated Users | Person, Username, Primary Email, Job Title, Manager, Department, Status, Deactivation Date, Last Login, User ID | Yes |
List of Devices | ID, Device Name, Device Details, Status, Creation Date, Last Updated | Yes |
List of Groups | Group ID, Name, Type, Description, Creation Date, Last Updated | Yes |
List of User Login Events | User ID, User Details, IP Address, Login Date, Status | Yes |
List of Users | Person, Username, Primary Email, Status, Last Login, User ID, Job Title, Manager, Department | Yes |
List of Users for a Given Application | ID, Email, Status, Scope | Yes |
List of Users with MFA Settings | Person, Username, Primary Email, Status, Last Login, MFA | Yes |
Password Policies | Name, Description, Assigned to Groups, Minimum length, Lower case letter, Upper case letter, Number (0-9), Symbol (e.g. ,!@#$%^&*), Does not contain part of username, Does not contain first name, Does not contain last name, Restrict use of common passwords, Password expiration (maxAgeDays), Warn user before expiration, Minimum password age (minAgeMinutes), Enforce password history (historyCount), Attempts before lockout (maxAttempts), Automatic Unlock (autoUnlockMinutes), Send lockout email, Show lockout failure | Yes |
Okta notes on proof types
List of Users
Note: By default, this proof type includes all users. Exclude decommissioned users if you receive a message indicating too many results.
List of Users with MFA Settings
Note: Use the Last Name filter to reduce the number of records returned if you receive a message indicating too many results. Select alphabetical ranges to include users whose last name falls alphabetically within those ranges.
This Hypersync supports importing a user list for an access review. See Importing a list of application users with a Hypersync for more information.
This Hypersync supports importing a company directory for an access review. See Importing a directory with a Hypersync for more information.
Rate limits
If you are experiencing time-out errors when collecting proof from Okta, review the Okta Rate limits overview documentation on the Okta developer site. It is possible that Okta's rate limits are preventing Hyperproof from collecting Okta proof. If necessary, you can purchase increased rate limits from Okta.
Okta proof permissions
Note: Hyperproof recommends creating a service account to generate the API key (note that the API key has the same permissions as the user who created it). The service account should be granted the Read-only Administrator role to allow the Hypersync to gather all necessary information.
If you prefer more granularity and only need to generate certain proof types, you can create a custom role with very specific permissions for those proof types. The required permissions by proof type are as follows:
Proof type | Required permissions |
Directory Integrations | View directories View agents |
Global Session Policies | Read-only Administrator |
Group Membership List | View groups View users and their details |
List of Admins | Super Administrator |
List of API Tokens | View API tokens |
List of Deactivated Users | View users and their details |
List of Devices | Read-only Administrator |
List of Groups | View groups |
List of User Login Events | Read-only Administrator |
List of Users | View users and their details |
List of Users for a Given Application | View applications and their details View users and their details |
List of Users with MFA Settings | View users and their details |
Password Policies | Read-only Administrator |
Okta does not provide any finer-grain permission controls to enable a read-only role that encompasses all the different proof types' functionality. Therefore, if you need to access all proof types, you must use at least the Read-only Administrator role, and to include the List of Admins proof type, you must have the Super Administrator role.
Additional documentation
Connection configuration
Authentication type: Custom
Custom authentication parameters: Okta Domain, API Access Token
Note: You only need to connect Hyperproof to the app once, and then you can create as many Hypersyncs as you need.
Additionally, you can create multiple Hypersyncs for a single control or label.
Tip: If you don’t know your access token or don’t have one, you can create one on the Okta Security > API page.
Certain cloud services offer specialized IP filtering options in their cloud consoles to lock down specific cloud API endpoints for security and compliance. You can use the Hyperproof static IP addresses to allow communication between Hyperproof Hypersyncs and your cloud service.
Hyperproof US IP addresses - 20.184.128.53, 52.159.252.1
Hyperproof EU IP addresses - 9.141.172.46, 4.185.45.100
Hyperproof Gov IP addresses - 4.155.77.155, 4.155.78.5, 4.155.8.97
See Hyperproof instances for more information.
